Most cannabis omnibus bills get read for what they permit. SB 3222, which Gov. JB Pritzker signed on June 12, 2026, permits a lot: adult possession limits doubled to 60 grams of flower, 10 grams of concentrate, and 1,000 mg of infused THC. Craft grower canopy went from 5,000 to 14,000 square feet. Dispensaries may run drive-thru and curbside pickup, stay open until 2 a.m., register for medical sales alongside adult-use, and accept telehealth-issued patient certifications. Qualifying conditions expanded. Fees dropped for small operators.
Read it as a security document instead and it says something different. Illinois just authorized four new ways for a dispensary to touch a customer, at hours when fewer staff are on site, while the state’s hemp-derived THC market gets folded into the licensed system on November 12. Each of those is a data flow that didn’t exist in your last risk assessment. The bill also loosens security requirements in places — which is a permission, not a recommendation.
Here’s the part operators keep getting wrong: regulators write the floor. Your liability doesn’t move down when the floor does.
Drive-Thru Is a Camera Problem and a Plate Problem
A drive-thru window changes three things at once.
It puts the transaction outdoors. Your surveillance coverage was designed for a sales floor, a vault, a back door, and a parking lot. A drive-thru lane needs its own camera geometry — the vehicle at the window, the product hand-off, the payment device, and the queue — at a resolution that survives being pulled for an audit six months later. Retrofitting cameras onto a new lane is where operators quietly end up with a second NVR, a second vendor, and a second set of default credentials nobody rotated. That is precisely the physical-cyber convergence problem most dispensaries have not solved on the cameras they already own.
It makes the vehicle part of the record. Drive-thru and curbside order-matching systems love license plates. They’re a convenient unique key: customer places order, staff matches plate to order, hand-off happens. Do not persist it. A stored plate is a direct link between a person, a purchase, and a location — the exact record that automated plate readers already collect independently, as Flock’s cross-border cannabis tracking made concrete this month. Capture the plate transiently, match the order, discard it at hand-off. If your POS or curbside vendor writes it to a customer profile by default, that’s a configuration change you make before launch, not after a subpoena.
It moves ID checks into a car. Age verification through a driver’s-side window, at night, under time pressure, with a line behind — that’s the environment where staff start photographing IDs “to check later.” The discipline is unchanged: verify, don’t store. Scan or inspect, record the boolean result and the timestamp, keep no image. Every one of the industry’s largest exposures this year came down to retained identity documents, a pattern the 2026 breach failure analysis traces in detail.
2 A.M. Closing Changes Your Threat Model, Not Just Your Schedule
Extended hours are a revenue decision made by operations and a risk decision inherited by everyone else.
Late-night retail is a different security posture: thinner staffing, fewer managers on site, delayed police response in some jurisdictions, and cash accumulating for longer between drops. The insider-risk math shifts too — the controls that work at 3 p.m. depend on a second person being present, and most dispensary loss already originates inside.
Concretely, before you extend hours:
- Re-baseline alarm and duress procedures for a two-person or one-person shift. Any control that assumes a manager on site fails at 1 a.m.
- Tighten POS permissions by time of day if your system supports it. Voids, refunds, discount overrides, and inventory adjustments after 10 p.m. should require a second authorization or generate an exception report someone actually reads the next morning.
- Change the cash-handling cadence. More hours, later hours, same drop schedule is how you end up with a five-figure till at closing.
- Confirm your camera retention still covers the added hours. Longer days mean more footage at the same storage — retention silently shortens unless you provision for it.
- Check your insurance. Operating-hours changes are frequently a disclosed condition in cannabis property and crime policies, and your cyber underwriters will ask about staffing controls too.
Telehealth Certifications Import Somebody Else’s Security
This is the sleeper provision. Illinois now permits medical certifications issued by telehealth, and adult-use dispensaries may register to serve medical patients. Both changes route clinical data toward retailers that have never held any.
A telehealth-certified patient arrives with a certification generated by a platform you don’t control, from a clinic you didn’t vet, carrying documentation you now have to validate and possibly retain. The cannabis telehealth sector is, as we’ve covered, the industry’s newest attack surface and its least regulated one — thin startups, shared EHR-adjacent tooling, and patient records that fall into the HIPAA gap depending on who holds them and why.
What to do about it:
Decide, in writing, what you retain from a certification. In most cases you need to confirm validity and record that you confirmed it. You do not need a copy of the certification document, the diagnosis, the physician’s notes, or a scan of the patient’s registry card sitting in a shared drive. A confirmation event with a timestamp and an operator ID is a defensible audit artifact. A folder of clinical PDFs is a breach waiting for a filename.
Treat the telehealth platform as a vendor even if you never signed anything with them. If patients arrive through a referral relationship, a co-marketing arrangement, or a platform that hands you verification data, you have a data flow with a third party. Vet it like one.
Separate medical from adult-use data paths. Dual registration is convenient at the counter and dangerous in the database. Patient status, conditions, and certification details should not land in the same loyalty profile as adult-use purchase history — that co-mingling is what turns a routine retail breach into a health-data incident under Illinois law and the growing set of state health-data statutes closing the HIPAA gap.
The November 12 Convergence
SB 3222’s hemp provisions align Illinois with the federal standard on November 12, 2026, recriminalizing hemp-derived products above 0.4 mg THC per container outside the licensed system. Under-21 hemp sales were banned immediately on signing.
For licensed dispensaries, that means a wave of former hemp customers — and, in some markets, former hemp retailers’ customer lists — arriving in the regulated channel in the fourth quarter. Two cautions:
Do not buy or absorb a hemp retailer’s customer database. Those records were collected under a different legal regime, usually without cannabis-grade consent language, frequently including retained ID images. Acquiring them imports liability with no corresponding asset. This is the same trap as the orphaned data problem after regulatory whiplash, just closer to home.
Expect a Q4 traffic spike to land on new channels. Drive-thru and curbside are exactly what an operator reaches for when volume jumps. Launching a new customer-data channel during your busiest quarter, at extended hours, with seasonal staff, is a predictable way to produce an incident. Launch it now, in a slow month, and let the process harden before demand arrives.
What “Loosened Security Requirements” Actually Means
When a state relaxes a prescriptive control — a camera angle, a storage spec, a staffing minimum — it removes a compliance obligation. It does not remove:
- Your obligations under Illinois’s biometric and privacy statutes, which are enforced by plaintiffs, not regulators, and which have already produced devastating ID-scanner litigation
- Your contractual security commitments to payment processors, banks, and landlords
- Your insurer’s conditions
- Your duty to the customer whose passport scan you kept for no reason
Take the operational relief. Keep the control if it was doing real work. The regulatory floor dropping is an invitation to spend that budget somewhere better, not to spend it on nothing.
Bottom Line
SB 3222 is a growth bill, and Illinois operators should treat it as one. But every convenience it authorizes moves a customer interaction somewhere new: into a car, into the middle of the night, or through a clinician you’ve never met. Those are the three places data governance historically fails — outdoors, understaffed, and third-party.
Do the boring version first. Map each new channel to the data it touches. Decide what you keep before the first transaction rather than after the first request. Configure the plate field off. Write the telehealth retention rule down. Re-baseline the late shift. None of it is expensive in August. All of it is expensive in December.
Illinois SB 3222 provisions summarized from the Illinois Department of Agriculture’s Spring 2026 rule update bulletin and contemporaneous coverage of the omnibus signing.



